security-review
Audit code and configs for security problems before shipping. Covers OWASP Top 10, secret leakage (API keys, private keys, browser-bundled secrets), auth/session flaws, injection (SQL, NoSQL, XSS), CORS, uploads, and dependency CVEs. Use this skill whenever the user mentions audit, security review, vulnerability, CVE, pentest, OWASP, secrets, auth review, compliance, or asks "is this safe to ship", even if they only say "check this for problems" about login, payments, or user data. Not for adding features (see stack skills) or designing systems (see system-design).
Pinned to revision 9bf36daa2e81, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/security-review/SKILL.md
- skills/security-review/evals/check-fixtures.sh
- skills/security-review/evals/evals.json
- skills/security-review/evals/files/leaky-app/.env
- skills/security-review/evals/files/leaky-app/billing.js
- skills/security-review/evals/files/leaky-app/deploy-key.pem
- skills/security-review/evals/files/leaky-app/routes/auth.js
- skills/security-review/references/owasp-checklist.md
- skills/security-review/references/threat-modeling.md
- skills/security-review/scripts/secrets-scan.sh
Every link opens the file at its source, pinned to the revision this page describes.